Asking as someone only passive interested in it (a friend is a developer), any thoughts about the dat protocol and beaker browser as an alternative or does my understanding of tor and dat require adjustment? Do they address the concern you’ve brought up in a meaningful enough way?
In my experience, that's harder to do than you might expect. Some years ago, I found some unmaintained software that worked for signing html. But I didn't find anything to verify signed pages. Just an old Firefox extension that no longer works.